CVE-2014-6051

Published Sep 30, 2014

Last updated 19 days ago

Overview

Description
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow.
Source
cve@mitre.org
NVD status
Modified
Products
enterprise_linux_server_aus, enterprise_linux_server_eus, fedora, libvncserver, debian_linux, solaris

Risk scores

CVSS 2.0

Type
Primary
Base score
7.5
Impact score
6.4
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
CWE-189

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.